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We discuss the Ping-Pong protocol which was proposed by Bostrom and Felbinger. We derive 
a simple trade-off inequality between distinguishability of messages for Eve and detectability of 
\ Eve for legitimate users. Our inequality holds for arbitrary initial states. That is, even if Eve 

prepares an initial state, she cannot distinguish messages without being detected. We show that 
the same inequality holds also on another protocol in which Alice and Bob use one-way quantum 
£N| ' communication channel twice. 

PACS numbers: 03.67.Dd 



I. INTRODUCTION 

In 2002, Bostrom and Felbinger 1!] proposed a quantum protocol which is called Ping-Pong protocol. Being different 
from other protocols such as BB84 or E91, this protocol uses two-way quantum communication. They showed a trade- 
off inequality between information gain by Eve and the error probability detected by Alice and Bob on the ideal setting 
of the protocol. That is, information gain by Eve is inevitably detected by Alice and Bob. While they insist that 
this protocol works as a secure direct communication as well as a key distribution protocol, there have been several 
discussions on its security from various points of view 0, d, 0, [E[ . The purpose of the present paper is not to discuss the 
security issue of the protocol but to give a simple derivation of another trade-off inequality between distinguishability 
of messages for Eve and detectability of Eve for legitimate users. The inequality holds for arbitrary initial states. 
Thus even if an initial state is prepared by Eve, she cannot distinguish the messages without being detected. As 
a byproduct, we show that the same inequality holds on a variant of the original protocol in which Bob sends his 
, quantum system twice to Alice. 

■ This paper is organized as follows. In the next section, we give a short description of the original Ping-Pong 
protocol. In section Hill a trade-off inequality is derived in a simple manner. In section [TVl a variant of the original 

■ protocol is given. It is shown that our trade-off inequality still holds on this variant. 
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II. PROTOCOL 



In this section we give a brief explanation on the simplest version of the protocols for Alice to send Bob one-bit 
message (or secret key). Bob first prepares a maximally entangled state \4>q) := -^(|11) + |00)). He sends one 

of the bipartite systems which is called system A. It is described by a Hilbert space TCa(— C 2 ). Another system 
possessed by Bob is called system B with its Hilbert space TCb(— C 2 )- Bob confirms Alice's receipt of the system 
A Q. Alice randomly chooses one from {Control, Message}. If she chose "Control", she lets Bob know it and they 
both make measurements of <j z (A) and a z {B) on their own systems respectively [7]. If their outcomes disagree, they 
know existence of Eve and abort the protocol. On the other hand, if Alice chose "Message" , she encodes her one-bit 
message to her system A. She does nothing on system A for the message 0. She operates a z (A) on it for the message 
1, which changes the phase with respect to |0). Alice sends back the system A to Bob. Bob makes a Bell measurement 
on the composite system A and B to know the encoded message. As pointed out in @, @, this naive protocol yields 
a simple "attack" that disturbs the message without being detected. That is, just an attack only on the second 
quantum communication from Alice to Bob does not affect the error probability in the control mode but can change 
the message while Eve cannot obtain any information. As claimed in 0, H[, this disadvantage may be avoided by 
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introducing authentication phase after the protocol or slightly modifying the protocol itself. We, however, do not 
treat this problem here. What we are interested in is whether Eve can distinguish the messages and 1 without being 
detected. 



III. ANALYSIS 



Let us see what Eve can do in this protocol. Eve prepares her own system E which is described by a Hilbert space 
He- We write the initial state of system E as |f2). She interacts it with system A when system A is sent between Alice 
and Bob. That is, she has two chances to obtain the information. Let us denote the first interaction by a unitary map 
W : Ha ®He — ► Ha ®He and the second interaction by V : Ha ®He — > Ha ®He- The state after the first attack 
is described by |\?) := W\(p (8) Q). The final state over the tripartite system A, B and E in a message mode becomes 
V\^) when Alice's message is and becomes Va z (A)\^) when Alice's message is f. Eve's purpose is to distinguish 
them. The states to be distinguished by Eve are 

Po := ti AB (V|*)<¥|V) 

Pi := tv AB {Vcr z (A)\^)^WM)V*). 

We employ fidelity [1, Q as a measure for (in)distinguishability of states. The fidelity between two states p and a is 

defined by F(p, a) :— try/ p l / 2 <rp 1 / 2 . ft takes 1 if and only if p — a and takes a nonnegative value less than 1 in general. 
The key lemma is the following which played an important role in [To| to derive a version of Wigner-Araki-Yanase 
theorem. 

Lemma 1 Suppose that we have two systems that are described by Hilbert spaces Hi and Hi, and a pair of pure states 
\4>o), \<t>i) G Hi Cg) Hi- If we put states on Hi as 

Pj ■= tri (\4>j)(^>j\), 

for j = 0, f , then for an arbitrary operator X on Hi, 

\(<h\X\<h)\ < \\X\\F( Po ,pi) 

holds, where \\ ■ \\ is an operator norm defined by \\X\\ := sup^^Q nrrjxrr ■ 

Proof: 

We consider an arbitrary positive-operator- valued measure (POVM) {E a } on Hi, that is, every positive operator E a 
acts only on Hi and satisfies J2 a E a = 1. We obtain 



\(<f>o\X\<t>i)\ =\J2(<t>o\EaX\cf> 1 )\ = \Y,(<t> \E 1 J 2 XE 1 J 2 \<j> 1 )\, 

a a 
1/2 

where we used the commutativity between E a and X. We further obtain 

\(<f*\X\<h)\ < Y,\(^\E 1 J 2 XE 1 J 2 \ ( f > i)\ 

(X 

< ^MEM^^E^X^XE^)^ 

a. 

< J2(ME a \M 1/2 (^\EM^ 2 \\xi 

where we used the Cauchy-Schwarz inequality to derive the second line and the definition of the operator norm to 
derive the third line. By using a property F(p, a) — inf e-.povm Y2 a \/ ^{pE a )tr(aE a ) which was shown in [ll|, H3 |. 
we take the infimum of the above inequality over all the POVMs to obtain 

\(MX\^i)\ < \\X\\F( Pa ,pi). 

It ends the proof. Q.E.D. 

In applying this lemma to Wigner-Araki-Yanase theorem, it was important to have a conserved quantity. Also 
in the Ping-Pong protocol, we have a conserved quantity. In fact, since the system B is kept by Bob during whole 
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the protocol, the attack does not give any effect on the operator on system B. That is, for any operator X on Hb, 
W*V*XVW = X and V* XV = X hold. We take the second equation and operate (*| and a z (A)\^) to it. We obtain 

(*\VXV<t z (A)\9) = (*\X* X (A)\9). 

Taking the absolute value of the above equation, we apply the lemma with Hi — Ha ®Hb, H2 = He, \<j>o) = V\*&) 
and \(f>i) = V cr z (A)\if!) to obtain, 

\\X\\F{p^ Pl )>mXa z (A)\m 

Thus the indistinguishability of the messages for Eve is bounded from below by a correlation function after the first 
attack. If we put X = o~ z (B), this correlation function becomes 

{9\a x (B)a x (A)\*) =p(0,0)+p(l,l) -p(0,l) -p(l,0) = 1 - 2p(a z (A) + ^(B)), 

where p(i,j) is probability for Alice and Bob to obtain <r z (A) = i and a z (B) = j respectively in \*ff). That is, this is 
a probability distribution of the outcomes in the control mode. Thus we obtain 

\l-2p(a z (A)^a z (B))\<F(p , Pl ). 

Note that this inequality holds for an arbitrary state over the tripartite state since we did not use its concrete 
form. Thus we proved the following theorem. 

Theorem 1 In the Ping-Pong protocol, Eve cannot distinguish the messages and 1 without being detected. In 
fact, if we put p(a z (A) ^ a z (B)) probability for Alice and Bob to obtain different outcomes in the control mode, 
indistinguishability measured by the fidelity is bounded as 

\l-2p(a z (A)^a z (B))\<F( Po , Pl ). 

Here the initial state can be arbitrary. Even if it was prepared by Eve, the above trade-off inequality still holds. 

It should be remarked that although the above trade-off inequality holds for arbitrarily prepared states, it does not 
mean that the protocol works in such cases. In fact, in such cases Alice and Bob cannot share the messages even if 
they do not detect Eve. That is, success in message sharing and information gain by Eve are different matters in this 
protocol. 

IV. A VARIANT OF THE PROTOCOL 

In the original Ping-Pong protocol Bob first sends a qubit to Alice and receives it in the end of the protocol. In 
this section, we consider its variant. After the confirmation of Alice's receipt of a qubit, Bob, instead of Alice, sends a 
message to Alice. For the definiteness, we describe the whole protocol in the following. Bob first prepares a maximally 
entangled state |0o) := ^(|11) + 1 00} ) . He sends one of the bipartite systems which is called system A. It is described 
by a Hilbert space Ha- Another system possessed by Bob is called system B with its Hilbert space Hb- Bob confirms 
Alice's receipt of the system A. Bob randomly chooses one from {Control, Message}. If he chose "Control", he lets 
Alice know it and they both make measurements of o~ z (A) and o~ z (B) on their own systems respectively. If their 
outcomes disagree, they know existence of Eve and abort the protocol. On the other hand, if Bob chose "Message" , 
he encodes his one-bit message to his system B. He does nothing on system B for the message 0. He operates a z (B) 
on it for the message 1, which changes the phase with respect to |0). Bob sends the system B to Alice. Alice makes 
a Bell measurement to the composite system A and B to know the encoded message. 

We can prove again the following theorem. 

Theorem 2 In the above variant of the Ping-Pong protocol, Eve cannot distinguish the message and 1 without 
being detected. Let us denote by P o Eve's final state corresponding to the message and P i one corresponding to the 
message 1. If we put p(a z (A) ^ a z (B)) probability for Alice and Bob to obtain different outcomes in the control mode, 
indistinguishability between P q and [i\ is bounded as 

\l-2p(a z (A)^a z (B))\<F( Po ^i)- 
Here the initial state can be arbitrary. Even if it was prepared by Eve, the above trade-off inequality still holds. 
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Proof: 

The proof runs in the same manner with the previous theorem. Eve, with her own system E, interacts system A 
and system B when they are sent from Bob to Alice. We denote by the state over system A, B and E after the 
first attack and denote the second attack by a unitary map U : Hb ®He —* Hb <&%e- In the message mode, the 
states Eve wants to distinguish are /j,q := tiAB{U\^f)(^\U*) and /ii := tr AB(Ua z (B)\^f)('^\a z (B)U*) Since the second 
attack does not change the operator on Ha, U*a z (A)U = a z (A) holds. We operate ■ cr z (j4)|\t) on this equation 
to obtain, 

{*\U*tr t {A)Utr,(B)\9) = (*\<r z (A)* z (B)\V). 

Applying Lemma[T]to the absolute value of the left hand side with Hi = Ha®Hb, H2 — He, X = a z (A), \<fio) = U\*f?) 
and \4>i) — Ua z (B)\^f), we obtain, 

\l-2p(a z (A)^a z (B))\<F( Po ,^). 
It ends the proof. Q.E.D. 



V. DISCUSSIONS 



In this paper, we treated the Ping-Pong protocol and derived a trade-off inequality between distinguishability of 
states for Eve and detectability for legitimate users. The inequality holds for arbitrary states that may be prepared 
even by Eve. We showed that the same inequality holds in a slightly different protocol in which the quantum 
communication is one-way. It, however, should be remarked that this trade-off relation does not directly mean the 
security of the protocols. For instance, Eve can change the message without being detected by making an attack 
only on the second communication phase. Furthermore, if Alice and Bob intend to use the protocols for direct 
communication, they need to confirm sufficiently many times the cleanness of the line before sending a message. In 
fact, otherwise Eve may obtain the message with non-negligible probability. Thus further investigation on definition 
and analysis of the security should be needed. 
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